A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel.

CVE-2026-11405 affects five Tenda firmware builds and can bypass password checks through an undocumented admin login path in /bin/httpd.

A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web…